cbcvebase.

Debian Jqueryui vulnerabilities

7 known vulnerabilities affecting debian/jqueryui.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2021-41184P3MEDIUMCVSS 6.5fixed in jqueryui 1.13.0+dfsg-1 (bookworm)2021
CVE-2021-41184 [MEDIUM] CVE-2021-41184: jqueryui - jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0... jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of
debian
CVE-2021-41182P3MEDIUMCVSS 6.5fixed in jqueryui 1.13.0+dfsg-1 (bookworm)2021
CVE-2021-41182 [MEDIUM] CVE-2021-41182: jqueryui - jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0... jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value
debian
CVE-2016-7103P3MEDIUMCVSS 6.1fixed in jqueryui 1.12.1+dfsg-1 (bookworm)2016
CVE-2016-7103 [MEDIUM] CVE-2016-7103: jqueryui - Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow ... Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function. Scope: local bookworm: resolved (fixed in 1.12.1+dfsg-1) bullseye: resolved (fixed in 1.12.1+dfsg-1) forky: resolved (fixed in 1.12.1+dfsg-1) sid: resolved (fixed in 1.12.1+dfsg-1
debian
CVE-2010-5312P3MEDIUMCVSS 6.1fixed in jqueryui 1.10.1+dfsg-1 (bookworm)2010
CVE-2010-5312 [MEDIUM] CVE-2010-5312: jqueryui - Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog wi... Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option. Scope: local bookworm: resolved (fixed in 1.10.1+dfsg-1) bullseye: resolved (fixed in 1.10.1+dfsg-1) forky: resolved (fixed in 1.10.1+dfsg-1) sid: resolved (fixed in 1.10
debian
CVE-2021-41183P3MEDIUMCVSS 6.5fixed in jqueryui 1.13.0+dfsg-1 (bookworm)2021
CVE-2021-41183 [MEDIUM] CVE-2021-41183: jqueryui - jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0... jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accep
debian
CVE-2022-31160P4MEDIUMCVSS 6.1fixed in jqueryui 1.13.2+dfsg-1 (bookworm)2022
CVE-2022-31160 [MEDIUM] CVE-2022-31160: jqueryui - jQuery UI is a curated set of user interface interactions, effects, widgets, and... jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on
debian
CVE-2012-6662P4MEDIUMCVSS 4.3fixed in jqueryui 1.10.1+dfsg-1 (bookworm)2012
CVE-2012-6662 [MEDIUM] CVE-2012-6662: jqueryui - Cross-site scripting (XSS) vulnerability in the default content option in jquery... Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo. Scope: local bookworm: resolved (fixed in 1.10.1+dfsg-1) bullseye: re
debian
Debian Jqueryui vulnerabilities | cvebase